← IdenTrust Services, LLC cases
Bugzilla #1933353
Self Reported Incident
IdenTrust: Incorrect response for OCSP validation
RESOLVED
FIXED
IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
On November 23, 2024, IdenTrust discovered an issue where a limited number of TLS certificates returned an unauthorized OCSP response during a maintenance window. The CA quickly remediated the issue and provided a complete incident report by December 6, 2024. The root cause was identified as a bug in the REST API that affected internal OCSP responders due to a database time zone mismatch. IdenTrust implemented several corrective actions, including fixing the API, enhancing logging, and improving alert systems. All action items were completed, and the incident was resolved by March 10, 2025.
Chronology
- IdenTrust discovered unauthorized OCSP responses for TLS certificates.
- IdenTrust deployed logging capabilities for OCSP responders.
Thread Activity
- IdenTrust Services, LLC — IdenTrust reported an issue with unauthorized OCSP responses discovered during maintenance.
- IdenTrust Services, LLC — IdenTrust provided a complete incident report detailing the unauthorized OCSP response issue.
- IdenTrust Services, LLC — IdenTrust updated on improvements to the alert system.
- IdenTrust Services, LLC — IdenTrust confirmed deployment of logging capabilities for OCSP responders.
- Mozilla representative — Mozilla queued the bug for closure.
Participants
IdenTrust Services, LLC
Mozilla representative
External References
Similar Local Cases
IdenTrust: Invalid special characters in S/MIME Certificates
IdenTrust: Approval of TLS certificate renewal without domain validation
IdenTrust: Missing Revocation Reasons in CRL
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
IdenTrust: Undisclosed Unrevoked ICAs
IdenTrust: Cross-signed root certificate mis-issuance
IdenTrust: TLS self audit testing below 3%
IdenTrust: Unauthorized OCSP responses for cross-signed roots